Ross ROSS = Recommend OSS · open-source software intelligence for agents

cyb3rfox/Aurora-Incident-Response

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders observed · 2026-08-28

github.com/cyb3rfox/Aurora-Incident-Response · JavaScript · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

23/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2276
  • days_rel: n/a
  • days_push: 1063
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1078 stars · 130 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A cross-platform Electron desktop application for documenting incident response investigations. It digitizes the SANS FOR508 'Spreadsheet of Doom' to help responders track findings, tasks, lateral movement, and timelines while producing reports.

Use cases

  • track findings and tasks during an incident response investigation
  • visualize lateral movement paths in a security incident
  • build a visual timeline of attacker activity
  • generate incident response reports from case notes
  • replace spreadsheets for DFIR case management

When to choose

  • you are an incident responder managing a DFIR case and need structured documentation
  • you want a free, offline desktop tool for tracking investigation findings and timelines
  • you want to move beyond ad-hoc spreadsheets for incident documentation

When to avoid

  • you need a team-based, server-backed incident management platform with multi-user collaboration
  • you need automated evidence collection or SIEM-style alerting rather than manual documentation
  • you require a mobile-first solution, as tablet support is not yet available

Facets

application · maturity maintenance

developer-tools documentation security developer-tools windows cross-platform incident-response dfir case-management forensics electron-app linux macos electron

1 source

Member repositories

RepositoryRoleHealth v2
cyb3rfox/Aurora-Incident-Responsemain23

For agents

markdown · JSON · MCP: product_card(name="cyb3rfox/Aurora-Incident-Response")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem